AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16036

HIGH · CVSS 7.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The miniOrange 2FA plugin for WordPress versions prior to 6.2.7 is vulnerable due to improper binding of the second authentication factor during the pre-login challenge, enabling attackers with knowledge of a user's password to reconfigure the second factor to their own control. This flaw can lead to account takeover, including access to administrator accounts, posing a significant risk to site security. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this vulnerability.

CVE
CVE-2026-16036
Severity
HIGH
CVSS
7.5
EPSS
0.30%
WordPress

Original NVD Description

The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor, allowing an attacker who knows a user's password to rebind that user's second factor to an attacker-controlled destination, complete the challenge, and take over the account, including administrator accounts.